CompTIA Security+ guideHigh-value skills

Security+ Zero Trust: Control Plane, Data Plane, and Policy Decisions

Watch one contractor request reach a policy engine, then see the same session end when the laptop’s posture changes.

Short answer

Zero trust refuses a permanent “inside means trusted” zone. A policy engine decides, a policy administrator carries out that decision on the control plane, and a policy enforcement point allows or ends the data path. SY0-701 uses those component names and also lists adaptive identity, threat scope reduction, and policy-driven access control. Zero trust is not a product, not the removal of a VPN, and not multi-factor authentication by itself.

Two vocabularies

NIST SP 800-207, finalized in August 2020, is the architecture paper. In that model the policy engine decides whether to grant access. The policy administrator executes the decision through the control plane. The policy enforcement point enables, monitors, and can terminate the connection on the data plane. The paper’s point is that the network location is not a reason to trust the subject.

SY0-701 uses the same three component names. Its control-plane list also includes adaptive identity, threat scope reduction, and policy-driven access control. Its data-plane list includes implicit trust zones, subject/system, and the policy enforcement point. Learn both layers. An item that says “policy engine” wants the decision. An item that says “enforcement point” wants the place that actually allows or drops the traffic. Do not answer with a vendor name.

Account lifecycle still belongs in the identity guide. This page is only the access decision after an account exists.

A contractor, twice

Priya is a contractor. The resource is a scheduling application that holds patient appointment notes. The first request comes from a clinic-managed laptop that reports disk encryption and a current management agent.

ComponentPlaneResponsibilityWhat happens for Priya
SubjectData plane, as the objectives name itThe person and the system making the requestPriya on the managed laptop
Policy enforcement pointData planeAllows, watches, or ends the pathForwards the request and later drops it
Policy administratorControl planeTells the enforcement point what the engine decidedPasses “allow read” and later “end the session”
Policy engineControl planeDecides from identity, posture, and the resourceAllows a read-only session, then denies it

The equivalent path, in words: Priya’s laptop reaches the enforcement point. That point does not decide. It asks the control plane. The administrator asks the engine. The engine sees a known contractor, a healthy device, and a sensitive app, and it allows a limited read. The administrator tells the enforcement point to open that path. Nothing in this step authenticates every packet by hand. The session is allowed, and it can be checked again.

An hour later the same laptop fails its disk-encryption report. Adaptive identity and policy-driven access control are the exam phrases for a decision that can change. The engine now denies the session because the device posture no longer matches the rule for that resource. The administrator instructs the enforcement point to terminate the path. Priya’s password did not change. The resource did not change. The context did.

What a zero-trust decision is not

A product labeled zero trust is not the architecture. Removing a VPN does not create the decision above. MFA can be one input to the engine. It is not the engine. “Inside the office” is the implicit trust zone the objectives tell you to stop treating as enough. Least privilege shows up as the limited read, not as a second login prompt on every click. Reevaluation is the second row of the story, when posture changed and the same subject lost the path.

Practice a Security+ item that names the component. The free questions will not draw this table.

Trust the source

Official sources

Exam policies can change. Use these primary sources for the most current details.